4.3
CVSSv2

CVE-2017-14633

Published: 21/09/2017 Updated: 07/12/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted audio file with vorbis_analysis().

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xiph.org libvorbis 1.3.5

debian debian linux 7.0

debian debian linux 8.0

debian debian linux 9.0

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

canonical ubuntu linux 17.10

Vendor Advisories

Several security issues were fixed in libvorbis ...
Debian Bug report logs - #876779 libvorbis: CVE-2017-14632 Package: src:libvorbis; Maintainer for src:libvorbis is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 25 Sep 2017 19:51:04 UTC Severity: important Tags: security, upstream ...
Debian Bug report logs - #876778 libvorbis: CVE-2017-14633 Package: src:libvorbis; Maintainer for src:libvorbis is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 25 Sep 2017 19:51:01 UTC Severity: important Tags: patch, security, up ...
Debian Bug report logs - #870341 libvorbis: CVE-2017-11333 OOM via crafted WAV file Package: src:libvorbis; Maintainer for src:libvorbis is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 1 Aug 2017 09:06:01 UTC Severity: important ...
An out-of-bounds read flaw was found in the way libvorbis handled processing of Ogg Vorbis format files This flaw could potentially be used to crash an application using libvorbis by tricking the application into processing specially crafted files ...
In XiphOrg libvorbis before 136, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0c, which may lead to DoS when operating on a crafted audio file with vorbis_analysis() ...